Here are today’s top cybersecurity stories for Wednesday, September 9, 2026.
“ShieldCrash” Defender Zero-Day Bypasses Last Week’s Patch, No Fix Yet
Researcher Nightmare Eclipse published a proof-of-concept exploit named ShieldCrash, defeating the patch Microsoft shipped last week for the ShieldBreak Defender flaw. The new exploit grants SYSTEM-level arbitrary file read on fully patched Windows 10, Windows 11, and Windows Server systems, and Microsoft has not issued a fix. BleepingComputer
Google Patches Seventh Actively Exploited Chrome Zero-Day of 2026
Google shipped Chrome 153.0.8010.36/37 to fix CVE-2026-87491, an out-of-bounds write bug in the V8 engine with an exploit already circulating in the wild. It marks the seventh Chrome zero-day Google has patched this year, and the company recommends updating browsers immediately. Help Net Security
Storm Ransomware Claims Ontario Office-Supply and Managed IT Provider Lowerys
The Storm ransomware group listed Lowerys, a 100-year-old office-supply, printing, and managed IT services provider based in Thunder Bay, Ontario, on its extortion site. The claim has not been independently confirmed, and Lowerys has not issued a public statement. RedPacket Security
Storm Ransomware Also Names Richmond Hill Manufacturer Flexmaster
The same group added Flexmaster, a Novaflex Group subsidiary in Richmond Hill, Ontario manufacturing flexible ducting and HVAC accessories, to its leak site the same day. As with the Lowerys claim, the listing remains unverified. UNDERCODE NEWS
New cPanel Flaw Lets a Mail Account Run Code as Root
cPanel disclosed CVE-2026-67401, an SQL injection flaw in its EmailTrack feature, letting an attacker who already holds a hosting account with mail privileges write arbitrary files and reach root code execution. Patched builds are available, and no public exploit or confirmed active exploitation had surfaced as of publication. The Hacker News
Alby Warns of Critical Flaw Exposing Internet-Facing Bitcoin Lightning Wallets
Alby disclosed a critical vulnerability in Alby Hub versions 1.7.0 through 1.18.5, letting an attacker take over a wallet and drain its funds, but only where the owner exposed the Hub directly to the internet. The company says one user has been affected and urges upgrading to version 1.24.0 and resetting the wallet access password. The Hacker News
CISA Releases Updated Insider Threat Mitigation Guide
CISA published a refreshed version of its Insider Threat Mitigation Guide, first issued in 2020, adding guidance for hybrid and remote work arrangements and risks tied to artificial intelligence. The guide targets security and HR professionals building or maturing insider threat programs across government and the private sector. CISA
Schneider Electric and Siemens Fix Critical ICS Flaws in September Patch Cycle
Schneider Electric patched a maximum-severity authentication flaw in its Modicon M580 controllers, tracked as CVE-2026-3869 with a CVSS score of 9.2, alongside high-severity bugs in its PowerLogic and EcoStruxure IT products. Siemens issued nine advisories the same day covering products including Reyrolle relays and its Industrial Edge Management platform. SecurityWeek
Android’s September Update Patches 180 Vulnerabilities
Google released its September 2026 Android security updates, fixing 180 vulnerabilities spanning the Framework, System, and Kernel components. The bulletin lists no vulnerabilities under active exploitation at the time of release. SecurityWeek
Phishing Campaign Chains Six Google Services to Hide Credential-Theft Links
Researchers described a large-scale phishing operation routing victims through six separate Google properties, including Google Meet, Search, and DoubleClick tracking links, to bypass email security filters. Victim addresses are encoded in a URL fragment stripped by browsers before any request reaches a server, hiding them from most scanners, and the campaign delivers either credential-harvesting pages or ScreenConnect remote-access malware. Dark Reading
Stay tuned for today’s in-depth analysis posts.






